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L (Amended) A security system for ft computer connected to a network of computers 
comprising: 

at least one security subsystem ass6ciated with said computer, said subsystem being 
configured to correlate events across a phirality of devices associated with said network of 
computers and to detect attacks on said/computer, 

and a secure link between said&ecurity subsystem and a master system enabling data 
communication therebetween; whereir 

said master system monitors Laid security subsystem through said secure link and 
registers information pertaining to attacks detected by said security subsystem. 


5. (Amended) A netwo 


at least one security sut system associated with said target network, said subsystem being 



configured to correlate events 
computers and to detect attack ; 


k security system for a target network of computers comprising: 


icross a plurality of devices associated with said target network of 
on said network; and 


a secure link between s aid security subsystem and a master system enabling data 
communication therebetween- wherein 

said master system mc nitors said security subsystem through said secure link and 
registers information pertainiri^ to the attacks detected by said security subsystem. 


8. (Amended) A network se curity system for a target network of computers comprising: 
at least one security subsysi em associated with said target network and configured to 

correlate events across a plurality of devices associated with said target network and to detect 

and register attacks on said target i letwork; 
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a secure link for da^a communication between said security subsystem and said master 

system; and 

testing means associated with said master system for generating pseudo-attacks on said 
target network initiated by said master system and detectable by said security subsystem; wherein 

said master system monitors said security subsystem through said secure link by 
comparing the pseudo-attacks generated by said testing means to the detected attacks registered 
by said security subsystem 



1 1 (Amended) A njethod for monitoring the integrity of a security subsystem associated 
with a target network of cbbiputers and configured to detect attacks on said network of 
computers comprising: 

correlating events adross a plurality of devices associated with said target network using 


said security subsystem; 

establishing a secure 


monitoring the status 


link for the transfer of data between said security subsystem and a 


master system hierarchically independent from said security subsystem; 


of said security subsystem through said secure link; and 


registering informatic n pertaining to the status of said security subsystem. 



13. (Amended) A seci rity system for a computer connected to a computer network comprising: 
at least one detection i cleans associated with said computer, said detection means being 
across a plurality of devices associated with said computer 
on said computer; 


configured to correlate events 
network and to detect an attac 


a master security system located outside said computer network; and 
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a secure link between! said detection means and said master security system enabling data 

communication therebetween i wherein 

said master security system monitors said detection means through said secure link and 

registers information pertaining jto attacks detected by said detection means. 

17. (Amended) A network security system for a target network of computers comprising: 
at least one detection meaAs associated with said target network, said detection means 

being configured to correlate ever ts across a plurality of devices associated with said computer 

network and to detect an attack on said network; 

a master security system lc cated outside said network; and 

a secure link between said detection means and said master security system enabling data 
communication therebetween; wherein 

said master security system [monitors said detection means through said secure link and 
registers information pertaining to attacks detected by said detection means. 



21 . (Amended) A method f on monitoring the integrity of a detection means associated 
with a computer, said computer being connected to a computer network, and configured to detect 
an attack on said computer, said method comprising the steps of: 

correlating events across a plurality of devices associated with said computer network 
using said detection means; 

establishing a secure link for thd transfer of data between said detection means and a 
master system hierarchically independent from said detection means; 

monitoring the status of said detection means through said secure link; and 
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